The monitoring of and access by an employer to corporate email accounts used by employees is a particularly sensitive matter, in which the need to protect the organization and the company’s assets must be balanced against employees’ right to privacy.
Recent case law has recognized the possibility of carrying out defensive checks of an employee’s electronic correspondence where there are reasonable grounds to suspect that unlawful conduct has occurred.
However, for such monitoring to be considered lawful, the verification process must satisfy the principles of necessity, relevance and proportionality, while avoiding generalized monitoring or measures that go beyond the purposes pursued.
From this perspective, particular importance must be attached to the distinction between a system involving the generalized monitoring and retention of data, which must comply with the safeguards provided for by applicable legislation, and a subsequent defensive investigation that is limited in scope and specifically aimed at verifying a particular unlawful act or conduct.
Any non-compliance of the general system for retaining logs and electronic correspondence does not, in itself, automatically render all emails subsequently retrieved inadmissible as evidence.
Such communications may, in fact, be used where they have been obtained in the course of a limited and proportionate defensive investigation based on a concrete suspicion of unlawful conduct.
In this context, the timing of the data acquisition is also of particular importance. Communications dating from before the adoption and acceptance of a specific company policy may, in fact, lack the necessary requirements of transparency and lawful processing and, consequently, may not be admissible in disciplinary proceedings or for the protection of the company’s interests.
The issue therefore requires consideration of at least three key aspects.
First, it is necessary to determine the nature and characteristics of the monitoring carried out, distinguishing generalized monitoring from defensive checks limited to verifying specific conduct.
Second, the relationship between the lawfulness of data retention and the subsequent admissibility of such data as evidence is particularly relevant. Specifically, it must be established whether a subsequent, targeted and proportionate search may justify the use of data originally retained as part of a system that did not comply with applicable legislation.
Finally, it is necessary to identify the temporal limit beyond which data obtained through the monitoring of electronic correspondence can no longer be regarded as admissible.
Accordingly, the lawfulness of the monitoring must be assessed on a case-by-case basis, taking into account the specific manner in which access was carried out and its actual necessity in light of the purpose pursued.
The Law Firm remains available to provide any further assistance or clarification on this matter.